Skip to main content

Govern your AI. Build on infrastructure you control.

Connect the AI clients your teams already use to one self-hosted control plane. Manage model access, tool permissions, credentials, and audit in your environment. Extend the runtime with capabilities your business owns.

Connect your teams to supported models from Anthropic, OpenAI, Google, and Groq

Your agents can act. Can you account for their access?

The questions your security team needs answered

  • Who authorized this agent to use this tool?
  • Which model received the request?
  • Which policy allowed or denied the action?
  • Where is the record when someone asks?

A shared control point for connected AI

  • Apply access rules to authenticated users and agents.
  • Route supported model requests through your gateway.
  • Check governed tool calls before execution.
  • Keep policy decisions, execution records, and usage in your environment.
The governance boundary

Your people. Your AI. Your rules.

SystemPrompt sits between connected AI clients, model providers, and tools. Your team controls the policies and the deployment, with a shared record of the traffic that passes through it.

See it run

Watch a governed agent work

A replay of a real session: policy checks pass, a human approves the risky call, and a leaked production key gets blocked. This example uses an embedded web agent; supported external clients can also connect through the model and MCP gateways.

Try the live demo

Interactive web demo on real AI. Register and the credit is on your account. No card required.

Operate it inside your perimeter.

Deploy the Rust runtime with PostgreSQL on infrastructure you control. Choose where model inference runs and which external services are reachable.

Your deployment

Run in your cloud or on premises. Your team controls configuration, upgrades, and network access.

Self-hosted runtime

Your model choices

Use supported hosted providers or local inference. Fully disconnected operation also requires local models, tools, and identity services.

Explicit inference destinations

Credentials outside prompts

Supply configured credentials to tool processes without putting them in prompts. Tool code and its network access remain part of your trust boundary.

Runtime credential injection

Evidence you can inspect

Review the identities, policies, outcomes, and usage recorded for governed requests.

Queryable audit records

Your monitoring stack

Use structured logs with your existing collection and investigation tools.

Structured JSON logs

Scoped access

Control which connected users and agents can access models and tools through configured permissions.

Central access policies

Controls can support your compliance programme. Deploying SystemPrompt does not itself confer certification.

Govern today. Build your platform on the same runtime.

SystemPrompt is a Rust library you compile with your own extensions. Start with enterprise governance, then add the tools, jobs, APIs, and domain capabilities that make the system yours.

Plan your evaluation

Do we need to replace our AI clients?

Use supported clients with configurable model or MCP endpoints. Route their traffic through SystemPrompt and apply the relevant identity and policy configuration. Requests that bypass the deployment are outside its governance boundary.

What does self-hosted mean for our data?

The runtime and database run in your environment. If you choose a hosted model provider or external tool, the corresponding requests leave that environment. Disconnected operation requires local inference and local dependencies.

How do we evaluate it?

Clone the public template, follow the setup documentation, and test a representative client and tool workflow. Verify an allowed call, a denied call, and the audit record before expanding the rollout. Evaluation and non-production use are free under the Core licence.

What do we license, and what do we own?

The template is MIT licensed. Core is source-available under BSL 1.1 and requires a commercial licence for production use; each version converts to Apache 2.0 after four years. Your proprietary extensions remain yours. Production rights, support, and updates follow your commercial agreement.

Can we add our own capabilities?

Yes. Compile trusted Rust extensions into your application to contribute routes, jobs, schemas, providers, and other capabilities. Use the governed execution interfaces for calls that need policy enforcement; custom code remains your responsibility.

What will we cover on a call?

Bring the clients, model providers, and tools you want to govern. We will discuss deployment constraints, the first workflow to evaluate, the evidence your security team needs, and production licensing.

Book a call

Let's talk
your implementation

A 30-minute call to scope what you need. We can implement it for you, or you can run it yourself. No prior setup or trial required. Prefer to try it first? Clone the template.

  • Implementation, done for you We install, configure, and roll it out across your team. Nothing to build first.
  • Setup & rollout How it fits your systems, your staff login, your security tools, and any custom needs
  • Licensing & pricing Volume pricing, service-level guarantees, and licence terms that fit your business

A focused 30-minute call. No preparation or prior evaluation needed.

1 You
2 Team
3 Details
Your information
No spam Book instantly 30-min call

Bring your first governance use case.

Tell us which AI clients and tools your teams use. We will map the deployment, controls, and evaluation with you.

Book a call